CybersecurityJobs.io
← Back to all jobs

Job Description

Carson and SAINT is hiring a Senior Penetration Tester for remote work focused on in-scope vulnerability discovery and actionable reporting.

Responsibilities

  • Perform comprehensive penetration testing against internal and/or external environments across organizations, covering network, servers, workstations, applications, API, and online/cloud services.
  • Assess and attempt to bypass existing information security controls.
  • Conduct network and application vulnerability assessments.
  • Produce penetration testing reports with technical details, risk analysis, and remediation recommendations for identified issues.
  • Participate in project-related meetings, including information gathering, solution design, and project checkpoint discussions.
  • Act as a subject matter expert for network security, application security, and attack and defense techniques, including countermeasures.

What You Will Do

  • Use up-to-date automated and manual penetration testing tools and techniques to support discovery, enumeration, exploitation, and reporting.
  • Work within permitted engagement activities, aligned to the rules of engagement.
  • Assist in developing rules of engagement and reporting documentation.
  • Partner with the client to provide remediation or mitigation strategies as required.

Team Mission

  • Deliver comprehensive, in-depth identification of exploitable vulnerabilities within agreed engagement scope to protect customer data and reputation.
  • Ensure testing does not negatively impact the confidentiality, availability, or integrity of client system data.

Requirements

  • Minimum 7+ years of experience as a network and application penetration tester.
  • Hold OSCP/OSCE, CREST, GPEN, CEH, or an equivalent certification.
  • University Degree or College Diploma in Computer Sciences, Information Technology, or a related field, or an equivalent combination of education and experience.

Preferred Skills and Expertise

  • Demonstrated hands-on experience (minimum 5-10 years) conducting external and internal penetration tests across operating systems, web applications, and networks.
  • Experience running and managing network and application vulnerability scanning and assessment tools.
  • Technical knowledge of current vulnerabilities, exploits, and tools (commercial and open source).
  • Strong understanding of security industry best practices and procedures.
  • Experience following security assessment frameworks and penetration testing methodologies, including both manual and automated testing.
  • Ability to research evolving exploits, techniques, and tools to support penetration testing efforts.
  • Experience developing security tools and using scripts/utilities to automate assessment and analysis activities.
  • Experience maintaining a target-rich lab environment to support training and development/testing of advanced exploits.
  • Experience sustaining an up-to-date penetration testing toolbox.

Certifications and Technical Alignment

  • OSCP, OSCE (OSCE noted as beneficial under professional offensive security certifications)
  • CREST, GPEN, CEH
  • GIAC security certifications (GPEN, GWAPT, GXPN)
  • Qualified/Licensed Penetration Tester (Q/LPT), Certified Penetration Tester (CPT)
  • CompTIA Certified Ethical Hacker (CEH)
  • CISSP, CISA, CISM, CRMP, CRISC, ISSMP
  • OSWE, OSCE noted as beneficial

Soft Skills

  • Excellent verbal and written communication skills, including clear and concise assessment reports with findings, recommendations, road maps, and actionable plans.
  • Exceptional customer service, communication, and interpersonal skills.
  • Ability to communicate and work with executives, peers, and employees at all levels.
  • Ability and willingness to work outside business hours (weekends/evenings).
  • Strong time management and organizational skills.
  • High degree of integrity, competence, adaptability, resilience, and initiative.
  • Maintain relevant industry certifications and willingness to work toward additional credentials.

Additional Desired Qualifications

  • Experience testing mobile applications, social engineering, phishing, vishing, physical security, wireless networks, and more.
  • Consulting experience leveraging offensive methodologies in red and blue team penetration testing.
  • Experience curating technical and non-technical documentation referencing internal processes and procedures.
  • Knowledge of security compliance policy, programs, processes, and metrics.
  • Ongoing research into security trends, new testing techniques, and best practices, with knowledge sharing across the team.

Location

  • Remote

Pay

  • USD 125,000 - 145,000 per year

Benefits

  • 401(k)
  • Dental insurance
  • Flexible spending account
  • Health insurance
  • Health savings account
  • Life insurance
  • Paid time off
  • Professional development assistance
  • Referral program
  • Retirement plan
  • Vision insurance

Similar Jobs